Splunk Enterprise vulnerabilities
212 known vulnerabilities affecting splunk/splunk_enterprise.
Total CVEs
212
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
2
Severity breakdown
CRITICAL5HIGH76MEDIUM123LOW8
Vulnerabilities
Page 1 of 11
CVE-2026-20253P1CRITICALCVSS 9.8KEVPoC≥ 10.2, < 10.2.4≥ 10.0, < 10.0.72026-06-10
CVE-2026-20253 [CRITICAL] CWE-306 CVE-2026-20253: In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated use
In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file oper
nvd
CVE-2024-36991P1HIGHCVSS 7.5ExploitedPoC≥ 9.2, < 9.2.2≥ 9.1, < 9.1.5+1 more2024-07-01
CVE-2024-36991 [HIGH] CWE-35 CVE-2024-36991: In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a
In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoint in Splunk Enterprise on Windows. This vulnerability should only affect Splunk Enterprise on Windows.
nvd
CVE-2023-46214P1HIGHCVSS 8.8PoC≥ 9.0, < 9.0.7≥ 9.1, < 9.1.22023-11-16
CVE-2023-46214 [HIGH] CWE-91 CVE-2023-46214: In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not safely sanitize exte
In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not safely sanitize extensible stylesheet language transformations (XSLT) that users supply. This means that an attacker can upload malicious XSLT which can result in remote code execution on the Splunk Enterprise instance.
nvd
CVE-2023-32707P2HIGHCVSS 8.8PoC≥ 8.1, < 8.1.14≥ 8.2, < 8.2.11+1 more2023-06-01
CVE-2023-32707 [HIGH] CWE-285 CVE-2023-32707: In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below ve
In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100, a low-privileged user who holds a role that has the ‘edit_user’ capability assigned to it can escalate their privileges to that of the admin user by providing specially crafted web requests.
nvd
CVE-2024-36985P2HIGHCVSS 8.8PoC≥ 9.2, < 9.2.2≥ 9.1, < 9.1.5+1 more2024-07-01
CVE-2024-36985 [HIGH] CWE-687 CVE-2024-36985: In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10, a low-privileged user that does not ho
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10, a low-privileged user that does not hold the admin or power Splunk roles could cause a Remote Code Execution through an external lookup that references the “splunk_archiver“ application.
nvd
CVE-2022-43571P2HIGHCVSS 8.8PoC≥ 8.1, < 8.1.12≥ 8.2, < 8.2.9+1 more2022-11-03
CVE-2022-43571 [HIGH] CWE-94 CVE-2022-43571: In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can execute arbi
In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can execute arbitrary code through the dashboard PDF generation component.
nvd
CVE-2026-20251P2HIGHCVSS 8.8≥ 10.2, < 10.2.4≥ 10.0, < 10.0.7+2 more2026-06-10
CVE-2026-20251 [HIGH] CWE-502 CVE-2026-20251: In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versio
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway versions below 3.10.6, 3.9.20, and 3.8.67, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could perform a Remote Code Execution
nvd
CVE-2026-76314P2HIGHCVSS 8.8≥ 10.4, < 10.4.2≥ 10.2, < 10.2.6+2 more2026-08-19
CVE-2026-76314 [HIGH] CWE-94 CVE-2026-76314: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could perform Remote Code Execution (RCE) by submitting crafted Splunk Web Manager Configuration content. The user could then access all relevant data and affect system integrity and availability. The vulnerability is pos
nvd
CVE-2025-20229P2HIGHCVSS 8.0≥ 9.4, < 9.4.0≥ 9.3, < 9.3.3+2 more2025-03-26
CVE-2025-20229 [HIGH] CWE-284 CVE-2025-20229: In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8, and Splunk Cloud Platform versions bel
In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8, and Splunk Cloud Platform versions below 9.3.2408.104, 9.2.2406.108, 9.2.2403.114, and 9.1.2312.208, a low-privileged user that does not hold the "admin" or "power" Splunk roles could perform a Remote Code Execution (RCE) through a file upload to the "$SPLUNK_HOME/var/run/splunk/apptemp" dire
nvd
CVE-2026-76310P2CRITICALCVSS 9.4≥ 10.4, < 10.4.2≥ 10.2, < 10.2.6+2 more2026-08-19
CVE-2026-76310 [CRITICAL] CWE-284 CVE-2026-76310: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the associated search job dispatch archive, recover session material, and use it to access all relevant data available to the report owner and affect system integrity, including by performing administrative
nvd
CVE-2026-76313P2HIGHCVSS 8.8≥ 10.4, < 10.4.2≥ 10.2, < 10.2.6+2 more2026-08-19
CVE-2026-76313 [HIGH] CWE-284 CVE-2026-76313: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could perform Remote Code Execution (RCE) by uploading a malicious knowledge bundle and causing it to be used by distributed search, which can allow for access to all relevant data and affect system integrity and availab
nvd
CVE-2026-76315P2HIGHCVSS 8.8≥ 10.4, < 10.4.2≥ 10.2, < 10.2.6+2 more2026-08-19
CVE-2026-76315 [HIGH] CWE-94 CVE-2026-76315: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could execute arbitrary code on the Splunk platform instance through Splunk Web Manager Configuration. The user could then access all relevant data and affect system integrity and availability on the Splunk platform insta
nvd
CVE-2026-76319P2HIGHCVSS 8.8≥ 10.4, < 10.4.2≥ 10.2, < 10.2.6+2 more2026-08-19
CVE-2026-76319 [HIGH] CWE-862 CVE-2026-76319: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a low-privileged user that d
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a low-privileged user that does not hold the fsh_manage capability could perform Remote Code Execution through Federated Search bundle selection. This could allow for access to all relevant data and affect system integrity and availability. The vulnerability is possible because th
nvd
CVE-2026-76351P2HIGHCVSS 8.8≥ 10.4, < 10.4.2≥ 10.2, < 10.2.6+2 more2026-08-19
CVE-2026-76351 [HIGH] CWE-918 CVE-2026-76351: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway ve
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could use crafted report notification data to cause Splunk Secure Gateway to send a request to the Splunk Enterprise Representational State Transfer (R
nvd
CVE-2024-53247P2HIGHCVSS 8.8≥ 9.3, < 9.3.2≥ 9.2, < 9.2.4+1 more2024-12-10
CVE-2024-53247 [HIGH] CWE-502 CVE-2024-53247: In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7, and versions below 3.4.261 and 3.7.13 o
In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7, and versions below 3.4.261 and 3.7.13 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could perform a Remote Code Execution (RCE).
nvd
CVE-2026-76311P2CRITICALCVSS 9.4≥ 10.4, < 10.4.2≥ 10.2, < 10.2.6+2 more2026-08-19
CVE-2026-76311 [CRITICAL] CWE-284 CVE-2026-76311: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the dispatch archive for an embedded report search job and use exposed session material to access all relevant data and affect system integrity on the Splunk platform instance. The vulnerability is possible
nvd
CVE-2026-76312P2CRITICALCVSS 9.4≥ 10.4, < 10.4.1≥ 10.2, < 10.2.6+2 more2026-08-19
CVE-2026-76312 [CRITICAL] CWE-284 CVE-2026-76312: In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who
In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read the Hypertext Markup Language (HTML) source of a page that embeds a Splunk report could use exposed session material to access all relevant data and affect system integrity. The vulnerability is possible because the dispatch archive download
nvd
CVE-2026-76253P3HIGHCVSS 8.8≥ 10.4, < 10.4.2≥ 10.2, < 10.2.6+2 more2026-08-19
CVE-2026-76253 [HIGH] CWE-269 CVE-2026-76253: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role wit
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule_search capability could run arbitrary Search Processing Language (SPL) commands with the highest level of system privilege and read every credential stored in the credential store, which can allow for disclosure and modification of all re
nvd
CVE-2026-76335P2HIGHCVSS 8.8≥ 10.4, < 10.4.2≥ 10.2, < 10.2.6+2 more2026-08-19
CVE-2026-76335 [HIGH] CWE-94 CVE-2026-76335: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an authenticated user who do
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an authenticated user who does not hold a role with the edit_manager_xml capability could write a malicious Splunk Web Manager Extensible Markup Language (XML) configuration. When the same user opens the affected Splunk Web Manager page, Splunk Enterprise runs attacker-controlled o
nvd
CVE-2026-76350P3HIGHCVSS 8.8≥ 10.4, < 10.4.2≥ 10.2, < 10.2.6+2 more2026-08-19
CVE-2026-76350 [HIGH] CWE-269 CVE-2026-76350: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role wit
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule_search capability could configure Portable Document Format (PDF) attachments in the email alert action workflow. When the email alert action runs, it could execute arbitrary Search Processing Language (SPL) commands with system-level priv
nvd
1 / 11Next →